Responsible AI Governance · Operationalized

Govern the AI you're racing to deploy.

Enterprises are adopting AI faster than they can control it. I help you do both — building the inventories, risk frameworks, controls, and audit trails that turn responsible-AI principles into governance that actually runs, on the ServiceNow platform you already trust.

NIST AI RMF EU AI Act ISO/IEC 42001 ServiceNow IRM AI Control Tower
01 — Why now

The gap isn't ambition. It's operational control.

Agents, models, and embedded AI now sprawl across clouds, SaaS tools, and business units — frequently invisible to the very teams accountable for risk. You can't govern what you can't see.

At the same time, the regulatory floor is rising. The EU AI Act is in force, and frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 are fast becoming the baseline that boards, buyers, and auditors expect.

Most organizations have policies. Few have controls that run — an inventory of every AI system, risk classified by use, owners assigned, monitoring live, and evidence ready. That's the work.

"AI governance is the newest estate that needs the oldest discipline — inventory, control, risk, and accountability."
— The throughline of 20 years in enterprise IT
02 — Services

From principles to running governance.

S-01

AI Inventory & Discovery

Find and catalog every model, agent, and AI-enabled system across the enterprise — including shadow AI — and bring it into a single governed register, built on CMDB/CSDM discipline.

S-02

Risk Framework Mapping

Translate NIST AI RMF, the EU AI Act, and ISO 42001 into your context — risk-classify AI by use case and map each obligation to a concrete, ownable control.

S-03

Control Design & Monitoring

Stand up the controls, workflows, and continuous monitoring that keep AI inside the lines — operationalized on ServiceNow IRM and AI governance tooling.

S-04

AI Portfolio Governance

Bring SPM-grade rigor to AI investment — intake, prioritization, and lifecycle oversight so AI initiatives are funded, tracked, and accountable, not scattered.

S-05

Policy-to-Control Translation

Turn responsible-AI policy and executive intent into the procedures, roles, and evidence that make governance real on the ground — and survive an audit.

S-06

Audit & Assurance Readiness

Assemble the documentation, lineage, and reporting that prove control to regulators, customers, and the board — with dashboards leadership will actually use.

03 — Why me

Governance pedigree, not a governance pitch.

AI governance is a new field crowded with two kinds of advisor: ethicists who can't implement, and platform engineers who don't understand governance. The hard part — and the rare one — is operationalizing principles into controls that run.

That's been my work for two decades. CMDB and asset management are the discipline of knowing what you own and proving you control it. Integrated risk is mapping obligation to control. SPM is portfolio governance. I've delivered all three for enterprises that can't afford to get governance wrong — now applied to AI.

15y
CMDB / CSDM & Asset ManagementThe exact inventory-and-control discipline AI governance requires — applied to Dell, BJC, Bank of America, and more.
IRM
Integrated Risk & Data GovernanceMapping process and policy to controls across complex, regulated IT estates.
SPM
Strategic Portfolio ManagementCIS-SPM certified — intake, prioritization, and lifecycle oversight at enterprise scale.
NOW
ServiceNow Platform Depth9+ years implementing on the platform now positioned as the enterprise AI control tower.
04 — Approach

How an engagement works.

01
Assess

Inventory the AI estate, surface shadow AI, and benchmark current governance against the frameworks that apply to you.

02
Frame

Risk-classify by use case and map each obligation to a concrete control, owner, and evidence requirement.

03
Operationalize

Build the controls, workflows, monitoring, and reporting — configured and validated on ServiceNow.

04
Transfer

Hand over a running program your teams can own, extend, and defend — with the documentation to prove it.

Ready to see and control your AI?

Whether you're standing up an AI governance program from zero or operationalizing one that's stuck on paper, let's scope what good looks like for your organization.